ITSI MCP tools
ITSI 5.0.1 provides read-oriented access to ITSI episode investigation context through Splunk MCP Server. Use these tools to retrieve episode details, impacted services and KPIs, related entities, external links, similar episodes, and stored summarization from authorized MCP-compatible clients.
Available ITSI MCP tools
The following ITSI tools support investigation workflows. ITSI 5.0.1 ships these predefined tool definitions in tools.conf; customers do not need to create the tool definitions manually.
| Tool | Purpose | Typical use |
|---|---|---|
SA-ITOA_get_episodes |
List and filter ITSI episodes. | Find active or recent episodes by lookback, severity, count, and sort order. |
SA-ITOA_get_episode_details |
Retrieve metadata for a specific episode. | Review title, status, severity, owner, duration, event count, and instructions. |
SA-ITOA_get_impacted_objects |
Retrieve affected services, KPIs, and entities. | Understand blast radius and prioritize investigation areas. |
SA-ITOA_get_external_links |
Retrieve linked external references. | Find related Jira tickets, ServiceNow incidents, runbooks, or reference URLs. |
SA-ITOA_get_similar_episodes |
Retrieve similar historical episodes. | Identify recurring patterns and previous resolution paths. |
SA-ITOA_get_episode_summarization |
Retrieve stored episode summarization. | Review AI-generated summary, timeline, impact, and suspected root causes when Event iQ Diagnose is enabled. |